{"id":241,"date":"2026-09-27T01:08:45","date_gmt":"2026-09-27T01:08:45","guid":{"rendered":"https:\/\/managedt.com\/blog\/chinese-speaking-threat-actor-exploits-wordpress-zyxel-flaws-government-data\/"},"modified":"2026-10-09T03:00:17","modified_gmt":"2026-10-09T03:00:17","slug":"chinese-speaking-threat-actor-exploits-wordpress-zyxel-flaws-government-data","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/chinese-speaking-threat-actor-exploits-wordpress-zyxel-flaws-government-data\/","title":{"rendered":"Chinese-speaking threat actor exploits WordPress and Zyxel flaws to steal government data"},"content":{"rendered":"<p>Defenders gain a clearer picture of a single, well-resourced adversary after GreyNoise documented a campaign that breached at least 49 organizations in 29 countries, compromised 996 Zyxel network devices in 48 countries, and pulled more than 18,500 records from a backend database. The activity, attributed to a Chinese-speaking threat cluster with links to the Red Heron group, shows how one operator can chain exploits across WordPress, network switches, firewalls, AI tooling, and virtualization platforms to reach sensitive government and law-enforcement data.<\/p>\n<h2>What the campaign targeted and what it stole<\/h2>\n<p>The attacker reached high-value entities by exploiting a pair of vulnerabilities in the WordPress Core component, tracked as CVE-2026-63030 and CVE-2026-60137 and collectively known as wp2shell. Public exploits for wp2shell appeared in mid-July 2026, with active exploitation recorded within days. GreyNoise observed the campaign starting at roughly the same time.<\/p>\n<p>Targets spanned small businesses and government organizations. One intrusion at an unnamed Western government organization stood out for its depth. After gaining initial access, the operator ran a custom wp2shell exploit and performed extensive Windows and security reconnaissance, checking Microsoft Defender, AMSI, available services, listening ports, local accounts, application restrictions, and database configuration.<\/p>\n<p>Over a 36-minute window, the threat actor tried 17 scripts to bypass AMSI, escalate privileges through token impersonation or theft, create a local administrator, and extract registry data. Credentials for a backend SQL database surfaced during that work. The attacker then used those credentials in a password-spraying attack against an internal SQL server and stole at least 18,566 records. According to GreyNoise, those records contained accounts, plaintext passwords, and personally identifiable information (PII) tied to government and law-enforcement agencies.<\/p>\n<p>The same actor also breached a Russian state organization in occupied Ukraine, which the researchers described as a red-on-red compromise.<\/p>\n<h2>The Zyxel switch compromise<\/h2>\n<p>On August 17, 2026, the threat actor began exploiting a high-severity vulnerability in Zyxel GS1900 Smart Managed Switches, tracked as CVE-2026-7273. The flaw gave the operator a path into 996 devices across 48 countries. From those switches, the attacker extracted device configurations, network information, and hashed root-level credentials.<\/p>\n<h2>Other technologies in scope<\/h2>\n<p>WordPress and Zyxel were not the only targets. GreyNoise confirmed attempts against several additional products, each through a known flaw:<\/p>\n<ul>\n<li>PAN-OS GlobalProtect, the Palo Alto Networks remote access platform.<\/li>\n<li>FlowiseAI, the open-weight AI workflow builder, via CVE-2026-56271.<\/li>\n<li>The Linux kernel&#8217;s Dirty Pipe flaw, tracked as CVE-2022-0847.<\/li>\n<li>Gitea, the self-hosted Git service, via CVE-2026-60004, the same critical issue earlier tied to Red Heron.<\/li>\n<li>Nuclio, a serverless framework, via CVE-2026-79756.<\/li>\n<li>SENAITE LIMS, a laboratory information management system, via CVE-2026-54569.<\/li>\n<li>Proxmox VE, the virtualization platform, via CVE-2023-54391.<\/li>\n<li>Ubiquiti UniFi OS, through three chained flaws tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. CISA has flagged all three as actively exploited since late June 2026.<\/li>\n<\/ul>\n<p>Not every flaw exploited in this campaign has been added to CISA&#8217;s Known Exploited Vulnerabilities catalog, a point GreyNoise flagged for defenders.<\/p>\n<h2>How the activity was detected<\/h2>\n<p>GreyNoise attributed the activity through its Global Observation Grid (GOG) sensor network. Scans and attacks traced back to the same IP address and had been recorded since early June 2026. The company also published a set of indicators of compromise covering hashes for backdoors and command-and-control infrastructure tied to the observed activity.<\/p>\n<h2>What defenders can do with this<\/h2>\n<p>The campaign gives defenders a concrete checklist. WordPress sites running unpatched Core should be treated as exposed, since wp2shell exploits are public and now actively used. Zyxel GS1900 switches need to be checked against the August 17 exploitation window and reviewed for the configuration data and hashed credentials GreyNoise said the attacker pulled. Organizations using PAN-OS GlobalProtect, FlowiseAI, Gitea, Nuclio, SENAITE LIMS, Proxmox VE, or Ubiquiti UniFi devices should confirm that the CVEs listed above are patched, since several of them are not yet in CISA&#8217;s KEV catalog despite active use in this campaign.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is the wp2shell WordPress vulnerability?<\/h3>\n<p>Wp2shell is a pair of flaws in the WordPress Core component, tracked as CVE-2026-63030 and CVE-2026-60137. Public exploits appeared in mid-July 2026 and were followed by active exploitation, including a campaign that breached at least 49 organizations in 29 countries.<\/p>\n<h3>How many devices were compromised through the Zyxel flaw?<\/h3>\n<p>GreyNoise observed 996 Zyxel GS1900 Smart Managed Switches compromised in 48 countries after exploitation of CVE-2026-7273 began on August 17, 2026. Extracted data included device configurations, network information, and hashed root-level credentials.<\/p>\n<h3>Who is linked to the campaign?<\/h3>\n<p>GreyNoise attributes the activity to a Chinese-speaking threat actor linked to the Red Heron group, the same cluster tied to exploitation of a critical flaw in the Gitea self-hosted Git service. Activity was recorded from early June 2026 and traced to a single IP address.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is the wp2shell WordPress vulnerability?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Wp2shell is a pair of flaws in the WordPress Core component, tracked as CVE-2026-63030 and CVE-2026-60137. Public exploits appeared in mid-July 2026 and were followed by active exploitation, including a campaign that breached at least 49 organizations in 29 countries.\"}},{\"@type\":\"Question\",\"name\":\"How many devices were compromised through the Zyxel flaw?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"GreyNoise observed 996 Zyxel GS1900 Smart Managed Switches compromised in 48 countries after exploitation of CVE-2026-7273 began on August 17, 2026. Extracted data included device configurations, network information, and hashed root-level credentials.\"}},{\"@type\":\"Question\",\"name\":\"Who is linked to the campaign?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"GreyNoise attributes the activity to a Chinese-speaking threat actor linked to the Red Heron group, the same cluster tied to exploitation of a critical flaw in the Gitea self-hosted Git service. Activity was recorded from early June 2026 and traced to a single IP address.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data\/\" target=\"_blank\" rel=\"nofollow noopener\">bleepingcomputer.com<\/a>.<\/p>\n<p><!-- seo-pro:slop-fixed --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A threat actor linked to Red Heron breached 49 organizations in 29 countries using WordPress wp2shell flaws and a Zyxel switch vulnerability.<\/p>\n","protected":false},"author":3,"featured_media":240,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-241","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/241","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=241"}],"version-history":[{"count":2,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/241\/revisions"}],"predecessor-version":[{"id":514,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/241\/revisions\/514"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/240"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=241"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=241"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=241"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}